150
2 Computer Viruses, Malicious Logic, and Spyware
E-mail is one of the most widespread methods of interaction between the intruder
and implants, since the information received as a result of operation of the implant is
transferred in an electronic letter to the intruder without participation of the victim.
2.3.4.4 Methods of Protection from Software Implants
The aim of protection from software implants can be considered in three different
variants:
• Prevent introduction of the software implant into the computer system;
• Identify the embedded software implant;
• Delete the embedded software implant.
In consideration of these variants, the solution to the task of protection from
software implants is similar to the solution to the problem of protecting computer
systems from viruses. As in the case with viruses, the task is solved by using means
of monitoring the integrity of the launched system and application software, as well
as integrity of information stored in the computer system and the events that are
critical for system functioning. For example, in order to ensure protection from
keyloggers, it is necessary to monitor integrity of system files and interface links of
the authentication subsystem. Moreover, for the purpose of reliable protection from
keyloggers, the administrator of the operating system must comply with the security
policy, according to which the administrator is the only one who can configure chains
of software modules participating in the user authentication process, access files of
these software modules, and configure the authentication subsystem itself. All these
measures have to be implemented as a complex.
However, these means are only effective when they are not exposed to the influence
of software implants that can
• Impose final results of control checks;
• Affect the information reading process and launch of controlled programs;
• Change the algorithms of functioning of control means.
In addition, it is extremely important to ensure activation of control means before
the beginning of action of an implant, or when the control was executed solely with
the help of control programs stored in ROM of the computer system.
Universal method of protection from introduction of software implants is the
creation of an isolated computer. A computer is considered isolated if the following
conditions are met:
• It contains a BIOS system without software implants;
• The operating system has been checked for the presence of implants;
• Unchanged state of BIOS and the operating system has been verified for a specific
session;
• The computer is not used to launch any programs except the ones that have been
checked for the presence of implants;
2 Computer Viruses, Malicious Logic, and Spyware
E-mail is one of the most widespread methods of interaction between the intruder
and implants, since the information received as a result of operation of the implant is
transferred in an electronic letter to the intruder without participation of the victim.
2.3.4.4 Methods of Protection from Software Implants
The aim of protection from software implants can be considered in three different
variants:
• Prevent introduction of the software implant into the computer system;
• Identify the embedded software implant;
• Delete the embedded software implant.
In consideration of these variants, the solution to the task of protection from
software implants is similar to the solution to the problem of protecting computer
systems from viruses. As in the case with viruses, the task is solved by using means
of monitoring the integrity of the launched system and application software, as well
as integrity of information stored in the computer system and the events that are
critical for system functioning. For example, in order to ensure protection from
keyloggers, it is necessary to monitor integrity of system files and interface links of
the authentication subsystem. Moreover, for the purpose of reliable protection from
keyloggers, the administrator of the operating system must comply with the security
policy, according to which the administrator is the only one who can configure chains
of software modules participating in the user authentication process, access files of
these software modules, and configure the authentication subsystem itself. All these
measures have to be implemented as a complex.
However, these means are only effective when they are not exposed to the influence
of software implants that can
• Impose final results of control checks;
• Affect the information reading process and launch of controlled programs;
• Change the algorithms of functioning of control means.
In addition, it is extremely important to ensure activation of control means before
the beginning of action of an implant, or when the control was executed solely with
the help of control programs stored in ROM of the computer system.
Universal method of protection from introduction of software implants is the
creation of an isolated computer. A computer is considered isolated if the following
conditions are met:
• It contains a BIOS system without software implants;
• The operating system has been checked for the presence of implants;
• Unchanged state of BIOS and the operating system has been verified for a specific
session;
• The computer is not used to launch any programs except the ones that have been
checked for the presence of implants;
